All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Azure Monitor Alert Abuse: Detecting Callback Phishing Campaigns
Threat actors are abusing Microsoft Azure Monitor Action Groups to send legitimate-looking callback phishing emails to bypass traditional security filters.
Google Play Protect Advanced Flow for Android Sideloading
Google introduces Advanced Flow to Play Protect, enhancing security for Android sideloading to combat financial fraud and malicious APK installations.
Quest KACE SMA CVE-2025-32975: Potential Exploitation in Education
Quest KACE Systems Management Appliance (SMA) faces potential active exploitation via CVE-2025-32975, primarily targeting the education sector. Patch now.
Trivy Supply Chain Attack Spreads CanisterWorm via 47 npm Packages
Attackers compromise 47 npm packages using CanisterWorm, a self-propagating threat leveraging ICP canisters following a major Trivy supply chain attack.
Russian Intelligence Phishing Targets Signal and WhatsApp Users
The FBI warns of sophisticated phishing campaigns by Russian intelligence targeting Signal and WhatsApp users to harvest credentials and bypass encryption.
Russian Intelligence Targets Commercial Messaging App Accounts
Russian intelligence services are exploiting commercial messaging applications through phishing to compromise accounts of U.S. government officials, military, and…
Advertisement
Beast Gang OpSec Fail: Ransomware Server Exposes TTPs
Beast Gang's OpSec failure exposes their cloud ransomware server, revealing aggressive tactics against network backups. Defenders gain insight into their TTPs.
Oracle Fusion Middleware RCE Flaw: Immediate Patch Required
A critical unauthenticated remote code execution (RCE) flaw in Oracle Fusion Middleware's Identity and Web Services Managers demands immediate patching.
Operation Alice Disrupts 373,000 Dark Web Fake CSAM Sites
International law enforcement's Operation Alice has shut down over 373,000 dark web sites offering fake CSAM, impacting criminal infrastructure.
Oracle Identity Manager RCE via CVE-2026-21992 — Patch Now
Oracle issued an emergency patch for CVE-2026-21992, a critical unauthenticated RCE flaw in Identity Manager and Web Services Manager. Immediate patching is required.
75 Trivy-Action GitHub Tags Hijacked in Supply Chain Attack
Attackers hijacked 75 tags in Aqua Security's Trivy GitHub Actions to exfiltrate CI/CD secrets, marking the second major breach in a single month.
CVE-2026-20131: Cisco FMC/SCC Deserialization Vulnerability Under Active Attack
CISA adds CVE-2026-20131, a critical deserialization vulnerability in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC), to KEV Catalog due…
CISA Adds 5 KEVs: Apple Buffer Overflow, Code Injections Exploited
CISA's KEV Catalog updated with 5 actively exploited vulnerabilities impacting Apple products, Craft CMS, and Laravel Livewire. Immediate patching is critical.
Interlock Ransomware Targets Cisco Firewalls via CVE-2024-20481
Interlock ransomware operators exploited a critical Cisco ASA vulnerability before public disclosure. Learn how to detect and mitigate these targeted attacks.
Smuggling of AI Servers to China: DOJ Indicts Three for Export Violations
Three California residents face charges for allegedly conspiring to smuggle restricted high-performance AI servers to China through deceptive front companies.
Android Security Safeguards and UK Cyber Reporting Mandates
Analysis of new Android live threat detection features, the Operation Alice takedown, and updated UK cybersecurity reporting regulations for 2024.
Mitigating Geopolitical Cyber Threats and Wiper Malware Impacts
Analysis of how geopolitical tensions drive destructive cyberattacks and technical strategies for CISOs to contain lateral movement and build resilience.
CVE-2024-20481: Critical Cisco FMC RCE Exploited in the Wild
CISA mandates federal agencies patch CVE-2024-20481, a 9.8 CVSS RCE vulnerability in Cisco Secure Firewall Management Center, following active exploitation.
CVE-2026-33017: Critical Langflow RCE Exploited within 20 Hours
CVE-2026-33017 is a critical RCE vulnerability in Langflow currently under active exploitation. Learn how to secure your AI orchestration and detect attacks.
GSocket Backdoor Analysis: Malicious Bash Script Delivery and Impact
Analysis of a malicious Bash script deploying the GSocket backdoor for persistent access, bypassing firewalls through advanced NAT traversal techniques.
Proton Mail Metadata Disclosure: Understanding Legal Data Requests
Analysis of Proton Mail's metadata disclosure to Swiss authorities and the FBI, highlighting the risks of de-anonymization via payment information.
Native Launches Multicloud Security Control Plane for Policy Enforcement
Native introduces a security control plane that translates and enforces consistent policies across AWS, Azure, GCP, and Oracle using provider-native APIs.
Navia Data Breach Exposes Health Information of 2.7 Million Users
Navia Benefit Solutions reports a significant data breach affecting 2.7 million people, involving the theft of personal and health plan information.
Cape Secures $100M to Mitigate Cellular Tracking and Metadata Risks
Cape raises $100 million to build a privacy-first MVNO, addressing critical cellular network vulnerabilities like IMSI catching and location tracking.